REDHAT-BUG-2450785: High severity Nginx NGINX Open Source vulnerability
The 32-bit implementation of NGINX Open Source has a vulnerability in the ngxhttpmp4module module, which might allow an attacker to over-read or over-write NGINX worker memory resulting in its termination, using a specially crafted MP4 file. The issue only affects 32-bit NGINX Open Source if it is built with the ngxhttpmp4module module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted MP4 file with the ngxhttpmp4module module.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2450785?
The severity of REDHAT-BUG-2450785 is high due to the potential for memory over-read or over-write, leading to application termination.
How do I fix REDHAT-BUG-2450785?
To fix REDHAT-BUG-2450785, update to the latest version of NGINX Open Source that addresses this vulnerability.
Which systems are affected by REDHAT-BUG-2450785?
REDHAT-BUG-2450785 specifically affects the 32-bit implementation of NGINX Open Source.
What type of attack vector is associated with REDHAT-BUG-2450785?
The attack vector for REDHAT-BUG-2450785 involves using specially crafted MP4 files to exploit the ngx_http_mp4_module.
What are the potential consequences of REDHAT-BUG-2450785?
The potential consequences of REDHAT-BUG-2450785 include unexpected termination of the NGINX worker processes and potential service disruption.